Trezor Supply Chain Breach Affects 81,000 Customers

Trezor Supply Chain Breach Affects 81,000 Customers

First seen 8 Sep 2026, 09:32 UTC BleepingcomputerInfosecurity-Magazine 54.6

Article Content

Browse articles
ThreatCluster

Trezor, a cryptocurrency wallet manufacturer, announced that a data breach at its logistics partner, ShipMonk, has impacted 81,000 customers, significantly more than the initial estimate of 14,000. The breach, disclosed on August 13, 2026, initially involved data from May 10 to August 8, 2026, but an update revealed that additional data from November 2019 to August 2021 was also compromised. The exposed information includes full names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor attributed the breach to ShipMonk's failure to delete data as per their contractual agreement. The company is considering legal action against ShipMonk and has warned affected customers about the increased risk of phishing attacks. Trezor confirmed that its own systems were not compromised and that all devices remain secure. The breach has raised concerns about the security practices of third-party vendors.

Key Points: • Trezor's breach now affects 81,000 customers, up from an initial estimate of 14,000. • The exposed data includes personal information such as names, emails, and shipping addresses. • Trezor is considering legal action against ShipMonk for failing to delete sensitive data.

Ask AI about this cluster

Timeline

2026-08-13
Initial breach disclosure
Trezor announced a data breach affecting nearly 14,000 customers due to a compromise at ShipMonk.
Bleepingcomputer
2026-09-04
Breach impact updated
Trezor revealed that the breach affected an additional 67,000 customers, raising the total to 81,000.
Infosecurity-Magazine
2026-09-08
Current status
Trezor warns customers about increased phishing risks and is in discussions with ShipMonk regarding the breach.
Infosecurity-Magazine